Mark RadarMARK RADAR
About
EN
Sign in
Event File CRYPTO Cryptocurrency Wallets

Fake NPM, RubyGems Packages Target Crypto Wallets and Credentials

1 reports · First detected 2026-08-20 · Last active 2026-08-20

Software supply-chain attacks exploit developers’ trust in open-source registries by publishing packages whose names closely resemble widely used libraries. NPM and RubyGems are central distribution channels for JavaScript and Ruby software, making typosquatting especially dangerous: a single mistaken dependency can introduce malicious code into a developer’s machine or a broader corporate environment, potentially exposing login credentials, financial information and digital assets.

Security researchers recently identified 56 malicious packages impersonating popular libraries across NPM and RubyGems. The packages were designed to automatically download and execute a Go-based information stealer during installation, with Windows systems as the main target. The malware sought browser usernames and passwords, payment-card data, cryptocurrency wallet information and seed phrases, which can allow attackers to recover wallets and take control of the assets they contain.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)